Forensics

Security Incident Report

Incident reports are an important part of the forensics investigation. In this security incident report, I document a DOS attack using remote desktop services (RDS) on port 3389. In the report I note the containment steps taken, counter measures deployed, and recommended non-countermeasures controls to mitigate future attacks.

Working with different file systems

As a forensics specialist it is important to know the difference between different file systems. In this report I go over Windows, Linux, and Mac file systems. Even though they share the same basic functions they have different ways of where and how they store information.